MMM ransomware has been updated and continues spreading in 2018

MMM ransomware is a serious cyber threat that uses a combination of RSA + AES + HMAC[1] encryption ciphers to lock files on the affected computer. Originally, malware appends .0x009d8a file extension. However, this year security researchers have already reported about three new file extensions used by this virus: .triple_m, .info and .mmm file extension. The latest ransom note is called GET_YOUR_FILES_BACK.html.
| Name | MMM ransomware |
| Discovered in | 2017 |
| Category | Crypto-virus |
| Extensions | .triple_m, .info, .mmm |
| Ransom notes | restore_0x009d8a_files.html, RESTORE_triple_m__FILES.html, GET_YOUR_FILES_BACK.html |
| The amount of ransom | 1.2 BTC |
| Elimination | To get rid of the virus, run a full system scan with FortectIntego. |
Traditionally, after data encryption, MMM ransomware drops a ransom note called restore_0x009d8a_files.html. However, it’s recent update TripleM ransomware present data recovery instructions in “RESTORE_triple_m__FILES.html” file.
The ransomware opens it via browser and provides victim’s “uniq identificator.” The note gives a brief explanation of what method was used to corrupt files (AES256+RSA-2048). The virus warns not to attempt to recover files without cyber criminals’ help; otherwise, the data might get corrupted.
According to the fraudsters, the victim has only six days to pay the ransom (buy the decryption key). The price of the ransom for MMM virus developers is 1.2 Bitcoin[2]. After paying the ransom, the victim should write to unransom@mail.com for data decryption instructions.
However, instead of contacting cyber criminals, you should find a way to remove MMM ransomware from the system. The right way to do it is to use a professional malware removal tool such as FortectIntego. Please do not attempt to delete the ransomware manually because if you do it incorrectly, you can do more harm than good.
We strongly recommend you to follow removal guidelines that will assist you in MMM ransomware removal. We have added these at the end of this post. Feel free to use them. If you are a German-speaking computer user, please seek for help on Dieviren.de site[3].
The analysis of TripleM ransomware – the latest version of the virus
TripleM (MMM) ransomware uses RSA-2048[4] cryptography and appends either .triple_m or .info file extension to targeted files. Following data encryption, ransomware creates the “RESTORE_triple_m__FILES.html” file, which is a ransom note.
Victims of the ransomware are asked to pay 0.25 Bitcoins for data recovery and sen dan email to unransom@mail.com. However, criminals are not going to wait for the payment for long. After one week, the size of the ransom is said to increase up to 0.5 Bitcoins. However, after three weeks the payment will reach 1 Bitcoin, which is an enormous sum of money. After the 4th week, criminals threaten to delete decryption key.
Though, you should still not rush into paying the ransom. Security experts are working on a decryption software. Thus, soon you might get a free data recovery solution. In the meantime, you should remove TripleM from the computer and try alternative data recovery methods presented at the end of this article.

Methods used for spreading file-encrypting virus
Computer viruses including spyware and malware are mostly distributed using shady techniques meant to deceive the computer user and make him/her install or open the dangerous file unwillingly.
To prevent installing such deceptive programs or opening suspicious files, always think before clicking on an email attachment,[5] link, or a questionable ad. Remember that even one inattentive click on a compromised content can place a malicious virus on your computer.
We also suggest you to read these tips on how to identify emails with a virus in them and tips on how to outsmart phishing scams.
Delete MMM or TripleM ransomware from the system
Do not wait and clean your computer from the malicious virus. For MMM ransomware removal, consider using anti-malware software (e.g., FortectIntego, MalwarebytesMalwarebytes), but do not forget to put your computer in a Safe Mode with Networking first.
Using an automatic spyware/malware removal tool is the easiest way to remove MMM ransomware. The malware or spyware removal tool will find files associated with the ransomware and kill them all at one time.
Although the virus recommended you not to try third-party data recovery tools, we suggest you not to listen to scammers and try every possible method to restore your files. Please follow the provided guidelines carefully.
Did this guide help?
Be the first to comment